Maintaining robust cybersecurity in a modern business environment is inherently complex. Commercial software relies on millions of lines of code, and even the most established technology vendors face immense challenges in identifying every hidden security flaw. A striking example of this challenge occurred recently in August 2026, when researchers demonstrated how accessible artificial intelligence tools could uncover critical vulnerabilities in the video conferencing application Zoom in fewer than twenty prompts.
This flaw permitted malicious actors to silently take over a participant device during any call involving screen sharing, across every major operating system including Windows, macOS, Linux, iOS, and Android. At Vertex Cyber Security, we have long recognised the strategic risks associated with desktop-installed communication tools, which is why our experts routinely favour using the web browser version of software such as Zoom.
Understanding the Zoom Screen-Sharing Vulnerability
The vulnerability was uncovered in the underlying protocol responsible for facilitating real-time annotations during screen-sharing sessions. Complex and obscure features within proprietary, closed-source software often hide overlooked programming errors.
Using publicly accessible artificial intelligence models, researchers guided automated systems to inspect these convoluted components. In under twenty prompts, the artificial intelligence successfully identified zero-click vulnerabilities and generated functional exploit mechanisms.
The risks associated with this specific defect were particularly notable for several reasons:
- Silent Execution: The attack required no user interaction or confirmation beyond simply joining a call where screen sharing was active.
- Cross-Platform Exposure: The defect impacted Zoom applications running across desktop and mobile platforms alike.
- Democratisation of Cyber Exploits: Historically, identifying such intricate defects required dedicated teams working for months. Artificial intelligence tools have dramatically lowered the barrier to entry for finding software flaws.
Zoom has since issued client and server patches to resolve these issues. However, the incident serves as a clear reminder of the inherent risks posed by installed software on user devices.
Why Installed Software Escalates Endpoint Risk
Software applications installed directly onto a computer operate with broad permissions and deep integration into the underlying operating system. When a vulnerability in an installed application is exploited, an attacker may gain direct access to local files, system processes, and corporate network connections.
Cybersecurity is hard because security teams must protect every potential access point, whereas an attacker needs to locate only a single unpatched feature. Proprietary desktop applications present a broad attack surface because every feature, module, and plugin must remain secure across continuous software updates.
The Web Browser Advantage: Sandboxing and Reduced Exposure
To address these continuous operational risks, Vertex Cyber Security adopts a proactive posture. We foresaw the potential for application-level vulnerabilities in installed communication tools, leading our team to default to the web browser version of platforms such as Zoom rather than running native desktop clients.
Utilising web-based applications provides key architectural advantages that can enhance an organisation’s security posture:
- Effective Process Isolation: Modern web browsers utilise strict process sandboxing. This isolates the web application from the broader operating system, restricting its access to sensitive local computer files and hardware.
- Simplified Patch Management: Web applications update dynamically from central servers. This eliminates the delay associated with deploying client-side updates across hundreds of individual staff devices.
- Reduced System Privileges: Web browsers limit the permissions granted to third-party code, which can help mitigate the severity of potential exploits.
While no software deployment model provides absolute immunity, leveraging web versions of popular tools can significantly reduce your corporate exposure to local device compromise.
Potential Strategies to Enhance Your Organisation’s Defensive Posture
Organisations seeking to minimise risks associated with client-side applications might consider the following proactive measures:
- Encourage Web-Based Application Usage: Consider establishing policies that encourage or mandate using web browser interfaces for third-party communication tools where technical functionality permits.
- Enforce Automated Update Policies: Ensure that operating systems, installed applications, and web browsers receive timely security updates to address newly disclosed vulnerabilities promptly.
- Implement Least Privilege Controls: Restrict administrative permissions on corporate devices to ensure that potential exploits cannot easily modify critical system settings.
- Conduct Regular Technical Audits: Periodic security audits and penetration testing can help identify unpatched software, misconfigurations, and vulnerable third-party dependencies before malicious actors exploit them.
Strengthening Your Cybersecurity Resilience with Vertex
Navigating software vulnerabilities and protecting corporate infrastructure requires ongoing vigilance and technical expertise. Artificial intelligence continues to transform the threat landscape, making proactive security strategies more crucial than ever before.
At Vertex Cyber Security, our team of expert penetration testers and security specialists is dedicated to providing clear, practical guidance without unnecessary complexity. Whether you require comprehensive penetration testing, ISO 27001 guidance, or tailored security advice, we are here to support your organisation.
To discuss how we can assist in evaluating your application security and improving your overall security posture, please contact the team at Vertex Cyber Security